{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:17:15.059Z","total":4,"returned":4,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day","title":"Lazarus pairs fake recruiter approaches with a Windows zero-day","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Defence and aerospace organisations in Western Europe, India and South America","sector":"Defense","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Lazarus Group (North Korea)","summary":"Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.","how_it_worked":"Operators posed as recruiters offering roles at legitimate companies, most plausibly approaching targets through LinkedIn or messaging apps, and steered them into downloading malicious files including a trojanised PDF. The pretext works because a defence engineer receiving a career approach has a legitimate reason to open an attached job description or assessment. Execution then escalated to SYSTEM through the AFD.sys zero-day, installing a kernel-mode rootkit. One compromised French organisation was reused as a launch point for spear-phishing further targets, borrowing its real domain and relationships as the next trust signal.","lessons":"Recruitment documents from unsolicited approaches should be opened only in a sandbox or a browser-based viewer, and application allowlisting stops the downloaded binary before the privilege escalation matters.","confidence":"Confirmed","sources":[{"title":"Lazarus hackers pair fake job offers with Windows zero-day exploit","url":"https://www.helpnetsecurity.com/2026/08/12/north-korea-lazarus-fake-job-offers/","publisher":"Help Net Security"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day"},{"title":"Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge","date":"2022","date_precision":"year","victim_org":"Unnamed aerospace company in Spain","sector":"Defense","country":"Spain","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the recruiter persona was operated manually over LinkedIn Messaging.","outcomes":["Espionage","Data Breach"],"loss_usd":null,"loss_note":"No financial loss reported; the objective was espionage.","records_affected":null,"threat_actor":"Lazarus Group (North Korea), Operation Dream Job","summary":"ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.","how_it_worked":"A fake recruiter contacted employees through LinkedIn Messaging claiming to be running a Meta hiring process. The candidate was sent two supposed C++ programming tests, Quiz1.exe and Quiz2.exe, packaged inside ISO images hosted on cloud storage; one printed 'Hello, World!' and the other computed Fibonacci numbers, so the tasks appeared genuine. Running them side-loaded a malicious DLL that installed the NickelLoader downloader, which fetched miniBlindingCan and LightlessCan. LightlessCan supports up to 68 commands and reimplements many Windows utilities internally rather than spawning visible processes, reducing the telemetry available to endpoint monitoring during the espionage phase.","lessons":"Recruitment materials should never be executed on corporate endpoints; disposable virtual machines for candidate exercises plus application allow-listing eliminate this entire vector.","confidence":"Confirmed","sources":[{"title":"Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company","url":"https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/","publisher":"ESET WeLiveSecurity"},{"title":"North Korea-linked Lazarus impersonates Meta on LinkedIn to attack an aerospace company in Spain","url":"https://www.eset.com/us/about/newsroom/press-releases/north-korea-linked-lazarus-impersonates-meta-on-linkedin-to-attack-an-aerospace-company-in-spain/","publisher":"ESET"},{"title":"Lazarus hackers breach aerospace firm with new LightlessCan malware","url":"https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding"},{"title":"Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF","date":"2022-03-23","date_precision":"day","victim_org":"Sky Mavis (Ronin Network / Axie Infinity)","sector":"Cryptocurrency","country":"Vietnam","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the recruiter persona and interview process were run by humans.","outcomes":["Cryptocurrency Theft"],"loss_usd":620000000,"loss_note":"173,600 ETH and 25.5 million USDC were drained; the value is commonly reported as roughly $540 million at the time of the hack and about $620-625 million at the time of disclosure, depending on the valuation date.","records_affected":null,"threat_actor":"Lazarus Group (North Korea); sanctioned by the US Treasury in April 2022","summary":"On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.","how_it_worked":"Attackers posing as a non-existent company recruited a senior engineer over LinkedIn with an unusually generous compensation package, running a plausible multi-round interview process to build credibility. The final offer arrived as a PDF; downloading and opening it on a company machine executed spyware that gave the attackers a foothold in Sky Mavis systems. From there they obtained the private keys for four of the nine Ronin validator nodes, and used a still-active allowlist permission previously granted by Sky Mavis to the Axie DAO to obtain a fifth signature, reaching the five-of-nine threshold needed to authorise withdrawals from the bridge.","lessons":"Validator key material should live in hardware security modules on isolated machines that never render untrusted documents, and delegated signing permissions must expire automatically rather than persist after a temporary need ends.","confidence":"Confirmed","sources":[{"title":"How a fake job offer took down the world's most popular crypto game","url":"https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game","publisher":"The Block"},{"title":"Hackers Used Fake Job Offer to Hack and Steal $540 Million from Axie Infinity","url":"https://thehackernews.com/2022/07/hackers-used-fake-job-offer-to-hack-and.html","publisher":"The Hacker News"},{"title":"Spear Phishing Fake Job Offer Likely Behind Axie Infinity's Lazarus $600m Hack","url":"https://www.infosecurity-magazine.com/news/fake-job-offer-behind-axie/","publisher":"Infosecurity Magazine"},{"title":"Hackers stole $620 million from Axie Infinity via fake job interviews","url":"https://www.bleepingcomputer.com/news/security/hackers-stole-620-million-from-axie-infinity-via-fake-job-interviews/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf","year":2022,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf"},{"title":"Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails","date":"2016-02","date_precision":"month","victim_org":"Bangladesh Bank (central bank of Bangladesh)","sector":"Financial Services","country":"Bangladesh","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Wire Fraud / Financial Loss","Service Disruption"],"loss_usd":81000000,"loss_note":"$101 million in fraudulent SWIFT transfers were executed, of which $81 million reached accounts in the Philippines and about $20 million sent to Sri Lanka was blocked; a portion of the Philippine funds was later recovered, leaving roughly $65 million outstanding.","records_affected":null,"threat_actor":"Lazarus Group (North Korea); US DOJ charged Park Jin Hyok in 2018","summary":"In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.","how_it_worked":"Emails from a fabricated job-seeker persona were sent to Bangladesh Bank employees with a link to a résumé hosted externally; retrieving it delivered malware that established remote access. The attackers dwelled for about a year, mapping the bank's network and the workstation used for SWIFT Alliance Access. They then deployed custom malware that manipulated the SWIFT client's database and print output so fraudulent messages would not appear on the confirmation printer, issued transfer instructions to the New York Fed over a weekend, and routed proceeds through Philippine bank accounts and casino junkets to launder them.","lessons":"Isolating the SWIFT terminal on its own segment with application allow-listing, and independent reconciliation of outbound payment messages, would have caught both the intrusion path and the tampered confirmations.","confidence":"Reported","sources":[{"title":"Hackers took years before stealing $81m from Bangladesh Bank: FBI","url":"https://www.newagebd.net/print/article/141463","publisher":"New Age Bangladesh"},{"title":"When North Korean hackers almost pulled off a billion-dollar heist from Bangladesh Bank","url":"https://www.thedailystar.net/tech-startup/news/when-north-korean-hackers-almost-pulled-billion-dollar-heist-bangladesh-bank-2115317","publisher":"The Daily Star"},{"title":"Lessons Learned From the Bangladesh Bank Heist","url":"https://www.isaca.org/resources/isaca-journal/issues/2023/volume-6/lessons-learned-from-the-bangladesh-bank-heist","publisher":"ISACA Journal"}],"entry_type":"incident","slug":"2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin"}]}